2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-22512" ,
"sourceIdentifier" : "info@cert.vde.com" ,
"published" : "2023-03-23T06:15:12.367" ,
2023-05-23 08:06:44 +00:00
"lastModified" : "2023-05-23T07:15:09.060" ,
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2023-05-23 08:06:44 +00:00
"source" : "info@cert.vde.com" ,
2023-04-24 12:24:31 +02:00
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
{
2023-05-23 08:06:44 +00:00
"source" : "nvd@nist.gov" ,
2023-04-24 12:24:31 +02:00
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
2023-05-23 08:06:44 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
2023-05-23 08:06:44 +00:00
"confidentialityImpact" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
2023-05-23 08:06:44 +00:00
"baseScore" : 9.8 ,
2023-04-24 12:24:31 +02:00
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
2023-05-23 08:06:44 +00:00
"impactScore" : 5.9
2023-04-24 12:24:31 +02:00
}
]
} ,
"weaknesses" : [
{
"source" : "info@cert.vde.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-798"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_backup_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "f21000400" ,
"matchCriteriaId" : "2B8FFA7A-1C91-4C5B-A1E0-F057A1B83B90"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:element_backup:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "18A32228-1E64-4F09-B8EA-F122F7F8EFBA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_s1_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2e.3.8.0" ,
"matchCriteriaId" : "1D85D801-4958-4949-B8C1-8CF486B463E8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:element_s1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "19031686-7D24-408D-9144-1286C2C288B7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_s2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2e.3.8.0" ,
"matchCriteriaId" : "F1AB1110-6B20-46CD-81EE-C893D02FED70"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:element_s2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E9BCEA27-93B4-4D04-8E2A-4A0CC4EA725E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2e.3.8.0" ,
"matchCriteriaId" : "3E3B1FD3-CFA7-4585-B58F-DE3C67C952B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2e.4.0.0" ,
"versionEndExcluding" : "2e.4.4.0" ,
"matchCriteriaId" : "290140CE-3093-42D1-8060-A1DF88695CE9"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:element_s3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "67ACACF9-DBAF-4C23-AD99-2966BC9DE24A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:element_s4_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "d21010400" ,
"matchCriteriaId" : "29167A22-1E33-4DD8-BD6D-9046F6D11394"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:element_s4:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1A2E6700-E663-4F91-8F2C-2D543A5B074D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:one_l_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2e.3.8.0" ,
"matchCriteriaId" : "99BB655C-9E6E-4373-9B87-1A012DFAFACB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:one_l:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6FE9CF95-00C5-4913-9BFE-B57F1014FE7C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:one_xl_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2e.3.8.0" ,
"matchCriteriaId" : "79C4C11C-02D8-4580-A2F6-23A7FD861CB7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:one_xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0CFDDC29-1017-4404-B7F1-2B935A3C44CD"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:varta:pulse_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "c21010800" ,
"matchCriteriaId" : "025EF312-0B07-4553-8AF7-EEDD80A65FC1"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:varta:pulse:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4E8517B-A421-44E3-850E-DD8D7C9A63FE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://cert.vde.com/en/advisories/VDE-2022-061/" ,
"source" : "info@cert.vde.com" ,
"tags" : [
"Third Party Advisory"
]
}
]
}